CVE Feed

    Dashboard / CVE / CVE-2018-25393

    CVE-2018-25393

    Navigate CMS 2.8.5 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by injecting directory traversal sequences in the id parameter. Attackers can send GET requests to navigate_download.php with path traversal payloads ../../../cfg/globals.php to access sensitive configuration files and system files outside the intended directory.

    Published:May 29, 2026
    Last Modified:Jul 15, 2026
    EPS:May 29, 2026
    EPSS Score:0.00565
    CVSS Score:6.5

    Affected Products

    Vendor
    Navigate
    Product
    Navigate Cms
    Vendor
    Naviwebs
    Product
    Navigate Cms

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High